ZCyberNews
中文

Malware

88 articles

Secret Blizzard

BOTNET

Secret Blizzard Upgrades Kazuar Backdoor Into P2P Botnet

May 16 · HIGH

secret-blizzardkazuarturla

Gremlin Stealer

STEALER

Gremlin Stealer Evolves: Crypto Clipping, Session Hijacking, Packed

May 15 · HIGH

gremlin-stealerinfostealercrypto-clipper

TrickMo

TROJAN

TrickMo Android Trojan Uses TON Blockchain for C2, SOCKS5 Pivots

May 12 · HIGH

trickmoandroidton

Macos

MALWARE

Google Ads, Claude Chats Push MacSync Infostealer to macOS Users

May 10 · HIGH

macosinfostealermalvertising

Winos 4.0

MALWARE

Fake OpenAI Repo on Hugging Face Pushes Rust Infostealer

May 9 · HIGH

hugging-faceopenaiinfostealer

NWHStealer

MALWARE

NWHStealer Uses Bun JavaScript Runtime to Evade Detection

May 8 · HIGH

nwhstealerbuninfostealer

OceanLotus

MALWARE

OceanLotus APT Uses PyPI Packages to Deliver ZiChatBot Malware

May 8 · HIGH

oceanlotusapt32zichatbot

darkworm

BACKDOOR

PamDOORa Backdoor Steals SSH Credentials via Linux PAM Modules

May 8 · HIGH

pamdooralinux-backdoorpam

Quasar Linux RAT

RAT

Quasar Linux RAT Targets Developers for Supply Chain Attacks

May 8 · HIGH

quasar-linux-ratsupply-chain-attackcredential-theft

TCLBANKER

TROJAN

TCLBANKER Trojan Targets 59 Banks, Spreads via WhatsApp and Outlook

May 8 · HIGH

tclbankerbrazilian-banking-trojanref3076

PCPJack

WORM

PCPJack Worm Steals Cloud Credentials, Wipes TeamPCP Infections

May 7 · HIGH

pcpjackteampcpcredential-theft

ZiChatBot

MALWARE

ZiChatBot Malware Spreads via PyPI Packages Using Zulip C2

May 7 · HIGH

pypizichatbotzulip

APT37

MALWARE

APT37 Targets Ethnic Koreans in China With Android BirdCall Malware

May 6 · HIGH

apt37birdcallandroid-malware

CloudZ

MALWARE

CloudZ RAT Hijacks Microsoft Phone Link to Steal SMS, OTPs

May 5 · HIGH

cloudzphenomicrosoft-phone-link

BufferZoneCorp

MALWARE

Poisoned Ruby Gems, Go Modules Hijack CI/CD Pipelines

May 2 · HIGH

supply-chain-attackruby-gemsgo-modules

Deep#Door

BACKDOOR

Deep#Door Python Backdoor Targets Windows Systems for Espionage

May 1 · HIGH

deep#doorpython-backdoorwindows-implant

Mini Shai-Hulud

MALWARE

Mini Shai-Hulud Attack Hijacks SAP, Lightning, Intercom Packages

May 1 · CRITICAL

supply-chain-attacknpmsap

LummaC2

MALWARE

CISA, FBI Warn of LummaC2 Infostealer Targeting Orgs

Apr 30 · HIGH

lummac2infostealercisa

DEEP#DOOR

BACKDOOR

DEEP#DOOR Python Backdoor Steals Browser, Cloud Credentials

Apr 30 · HIGH

deep#doorpython-backdoorcredential-theft

Pypi

MALWARE

PyTorch Lightning Compromised in PyPI Supply Chain Attack

Apr 30 · CRITICAL

pypisupply-chaincredential-theft

Silver Fox

BACKDOOR

Silver Fox Targets Russia, India With ABCDoor Backdoor

Apr 30 · HIGH

silver-foxabcdoorvalleyrat

mini Shai-Hulud

MALWARE

SAP npm Packages Hijacked in Credential-Stealing Supply Chain Attack

Apr 29 · CRITICAL

supply-chain-attacknpmsap

LofyGang

STEALER

LofyGang Returns With Minecraft-Targeted LofyStealer Malware

Apr 28 · HIGH

lofyganglofystealerminecraft

VECT

RANSOMWARE

VECT 2.0 Ransomware Wiper Bug Destroys Files Over 131KB

Apr 28 · CRITICAL

vectransomwarewiper

VECT Ransomware

RANSOMWARE

VECT Ransomware Wiper Bug Destroys Data, Not Just Encrypts

Apr 28 · CRITICAL

vect-ransomwarewiperraas

GlassWorm

STEALER

73 Fake VS Code Extensions Deliver GlassWorm v2 Info-Stealer

Apr 27 · HIGH

glasswormvs-codesupply-chain-attack

Fast16

MALWARE

Fast16 Malware Resurfaces in Supply Chain Attacks Abusing Trusted

Apr 27 · HIGH

fast16supply-chain-attackrmm-abuse

GlassWorm

MALWARE

GlassWorm Malware Returns via 73 OpenVSX Sleeper Extensions

Apr 27 · HIGH

glasswormopenvsxsupply-chain-attack

Axios

RAT

Axios npm Supply Chain Attack Delivers Cross-Platform RAT

Apr 26 · CRITICAL

axiossupply-chainnpm

Brushworm

MALWARE

BRUSHWORM Backdoor and BRUSHLOGGER Keylogger Hit South Asian Bank

Apr 26 · HIGH

brushwormbrushloggerelastic-security-labs

CrystalX

RAT

CrystalX RAT Combines Spyware, Stealer, and Prankware in MaaS Offering

Apr 26 · HIGH

crystalxratmalware-as-a-service

Operation Triangulation

MALWARE

Kaspersky Details Coruna Exploit Kit Behind Operation Triangulation

Apr 26 · CRITICAL

operation-triangulationcorunaios-exploits

VoidLink

ROOTKIT

VoidLink Rootkit Framework Combines LKM and eBPF for Linux Persistence

Apr 26 · HIGH

voidlinklinux-rootkitebpf

Fast16

MALWARE

Pre-Stuxnet Malware 'Fast16' Targeted Iranian Precision Software

Apr 24 · HIGH

fast16stuxnetiran

Supply Chain Attack

MALWARE

Bitwarden CLI Compromised in Checkmarx Supply Chain Attack

Apr 23 · CRITICAL

supply-chain-attackbitwardennpm

CanisterSprawl

WORM

CanisterSprawl Worm Hijacks npm Packages, Steals Developer Tokens

Apr 23 · HIGH

supply-chainnpmmalware

Supply Chain

MALWARE

Checkmarx KICS Supply-Chain Breach Hits Docker, VS Code

Apr 23 · CRITICAL

supply-chaincheckmarxkics

Lotus Wiper

WIPER

Lotus Wiper Strikes Venezuelan Energy Sector in Destructive Campaign

Apr 23 · CRITICAL

lotus-wipervenezuelaenergy-sector

Mirai

BOTNET

Mirai Botnet Exploits D-Link Router Flaw CVE-2025-29635

Apr 23 · HIGH

miraibotnetd-link

Lazarus Group

MALWARE

North Korean Hackers Steal $12 Million in Crypto via Trojanized

Apr 23 · HIGH

north-koreacryptocurrencymalware

Trigona

RANSOMWARE

Trigona Ransomware Deploys Custom Exfil Tool for Faster Data Theft

Apr 23 · HIGH

trigonaransomwaredata-exfiltration

Browser Hijacking

STEALER

Fake TradingView AI Agent Site Drops Browser-Hijacking Malware

Apr 22 · HIGH

malwarebrowser-hijackingphishing

Harvester

BACKDOOR

Harvester Deploys Linux GoGra Backdoor via Microsoft Graph API

Apr 22 · HIGH

harvestergogralinux

Kyber

RANSOMWARE

Kyber Ransomware Deploys Post-Quantum Encryption in Attacks

Apr 22 · HIGH

ransomwareencryptionwindows

Energy

WIPER

Lotus Wiper Targets Venezuelan Energy Sector Before US Intervention

Apr 22 · HIGH

wiperenergyvenezuela

The Gentlemen

RANSOMWARE

The Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMware

Apr 22 · HIGH

ransomwareraasesxi

Infostealer

MALWARE

Fake Google Antigravity Installer Steals Accounts via Trojanized AI Tool

Apr 21 · HIGH

infostealergoogleai

Kyber

RANSOMWARE

Kyber Ransomware Deploys Dual Payloads for Windows and VMware ESXi

Apr 21 · HIGH

ransomwarevmwareesxi

Apple App Store

MALWARE

Malicious Crypto Apps Hijack Recovery Phrases from Apple App Store

Apr 21 · HIGH

apple-app-storecryptocurrencysupply-chain

NGate

MALWARE

NGate Malware Trojanizes HandyPay App to Steal Brazilian NFC Data

Apr 21 · HIGH

androidmalwarengate

Ngate

MALWARE

NGate Malware Uses AI to Evade Detection in Trojanized NFC Apps

Apr 21 · HIGH

ngateandroidai-malware

Purerat

MALWARE

PureRAT Malware Evades Detection with PNG-Stashed Payloads

Apr 21 · HIGH

pureratfilelessevasion

FakeWallet

MALWARE

FakeWallet Crypto Stealer Infects iOS Devices via Apple App Store

Apr 20 · HIGH

ioscryptocurrencyphishing

Gh0st Rat

RAT

Gh0st RAT and CloverPlus Adware Deployed in Dual-Payload Campaign

Apr 20 · HIGH

gh0st-ratadwaremalware-campaign

Infostealer

DROPPER

MiningDropper Framework Delivers Infostealers, RATs to Android Devices

Apr 20 · HIGH

androidmalwaredropper

The Gentlemen

RANSOMWARE

The Gentlemen Ransomware Deploys SystemBC Proxy for C2 Evasion

Apr 20 · HIGH

ransomwareraassystembc

Chrome

MALWARE

108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data

Apr 19 · HIGH

chromesupply-chainsession-hijacking

Mirax

RAT

Mirax Android RAT Infects 220,000 Users via Meta Ads, Creates SOCKS5 Proxy

Apr 19 · HIGH

androidratmalvertising

Omnistealer

MALWARE

Omnistealer Malware Harvests Passwords, Crypto Wallets via Blockchain C2

Apr 19 · HIGH

infostealerblockchaincredential-theft

Lumma Stealer

STEALER

Lumma Stealer Campaign Deploys Sectop RAT via Malicious PDFs

Apr 18 · HIGH

lumma-stealersectop-ratarechclient2

Mirai

BOTNET

Mirai Variant Nexcorium Exploits DVR Flaw to Build DDoS Botnet

Apr 18 · MEDIUM

botnetiotddos

Initial Access

RAT

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Attacks

Apr 18 · HIGH

ratsocial-engineeringinitial-access

Information Stealer

STEALER

Fake Proton VPN Sites and Gaming Mods Spread NWHStealer Malware

Apr 17 · HIGH

malwareinformation-stealerwindows

Payouts King

RANSOMWARE

Payouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH Backdoors

Apr 17 · HIGH

ransomwareevasionqemu

Malware Delivery

MALWARE

Fake Adobe Reader Downloads Deploy ScreenConnect via In-Memory Loader

Apr 16 · HIGH

malware-deliverydefense-evasionscreenconnect

Turkey

RANSOMWARE

JanaWare Ransomware Campaign Targets Turkish Homes and SMBs for Six Years

Apr 16 · HIGH

ransomwareturkeyadwind

Evasion

BOTNET

PowMix Botnet Targets Czech Workforce with Randomized C2 Traffic

Apr 16 · HIGH

botnetevasionczech-republic

Adware

MALWARE

Adware Campaign Hijacks DNS to Expose Thousands of OT and Government Endpoints

Apr 15 · HIGH

adwaredns-hijackingoperational-technology

Espionage

MALWARE

AgingFly Malware Targets Ukrainian Government and Hospitals

Apr 15 · HIGH

malwareespionageukraine

Wordpress

BACKDOOR

EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands of

Apr 15 · HIGH

wordpresssupply-chainbackdoor

Mobile Threat

BOTNET

Mirax Android RAT Evolves with Proxy Network and Data Theft Capabilities

Apr 15 · HIGH

androidmobile-threatproxy-botnet

Adware

MALWARE

Signed Adware Tool Disables Antivirus with SYSTEM Privileges

Apr 15 · HIGH

adwareendpoint-securityprivilege-escalation

Macos

MALWARE

Fake Ledger Live App on Apple App Store Steals $9.5M in Cryptocurrency

Apr 14 · HIGH

macoscryptocurrencysupply-chain

Janela Rat

RAT

Janela RAT Campaign Targets Latin American Finance with Fake MSI Installers

Apr 14 · HIGH

janela-ratlatin-americafinancial-sector

Chrome Extensions

MALWARE

Malicious Chrome Extensions Hijack OAuth Tokens, Deploy Backdoors

Apr 14 · HIGH

chrome-extensionsoauth2supply-chain

Proxy Botnet

RAT

Mirax Android RAT Steals Credentials, Enslaves Phones for Proxy Network

Apr 14 · HIGH

androidratproxy-botnet

Plugx

WORM

PlugX USB Worm Evolves with DLL Sideloading for Cross-Continent Spread

Apr 14 · HIGH

plugxusb-wormdll-sideloading

Macos

MALWARE

ClickFix Mac Malware Campaign Uses Fake Apple Page to Deliver Payloads

Apr 13 · MEDIUM

macossocial-engineeringjamf

Supply Chain

RAT

CPUID Software Downloads Compromised, Delivered STX RAT Malware

Apr 13 · HIGH

supply-chainratcpuid

Russian-speaking threat actor

RAT

CPUID Website Compromised to Distribute Trojanized System Utilities

Apr 13 · HIGH

supply-chainstx-ratcpuid

Plugx

RAT

Fake Claude AI Website Delivers PlugX RAT via DLL Sideloading

Apr 13 · HIGH

plugxdll-sideloadingsupply-chain

Janelarat

RAT

JanelaRAT Evolves with New Anti-Analysis and Data Theft Capabilities

Apr 13 · HIGH

janelaratremote-access-trojanlatin-america

Janelarat

RAT

JanelaRAT Malware Campaign Targets Latin American Financial Sector

Apr 13 · HIGH

janelaratbx-ratlatin-america

Spear Phishing

MALWARE

LucidRook Malware Targets NGOs and Universities in Taiwan via Spear-Phishing

Apr 13 · HIGH

malwarespear-phishinglua

REF6598

RAT

Obsidian Plugin Ecosystem Abused to Deliver PhantomPulse RAT in Targeted Campaign

Apr 13 · HIGH

obsidianphantompulserat

Python

BACKDOOR

VIPERTUNNEL Python Backdoor Evades Detection via Fake DLL and Obfuscated Loader

Apr 13 · HIGH

backdoorpythonobfuscation

ClickFix

MALWARE

ClickFix Malware Campaign Evades macOS Defenses via Script Editor

Apr 12 · HIGH

macossocial-engineeringclickfix

Plugx

MALWARE

Fake Claude AI Site Delivers PlugX Malware in Trojanized Installer

Apr 12 · HIGH

phishingplugxai